mediumMultiple Choice
PT0-002 Practice Question: A penetration tester is using theHarvester tool…
A penetration tester is using theHarvester tool to gather email addresses and subdomains for a target domain. Which source is theHarvester commonly configured to use for passive reconnaissance?
⚠ Common exam trap
CompTIA often tests the distinction between passive and active reconnaissance, and the trap here is that candidates confuse Shodan (a passive search engine for devices) with theHarvester's passive email/subdomain gathering, or assume DNS zone transfer is passive when it is an active query that requires direct server interaction.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Google search
TheHarvester is a passive reconnaissance tool that collects emails, subdomains, and other data from public sources without directly interacting with the target. Google search is a primary source because theHarvester uses Google's search engine via its API or scraping to find indexed pages containing email addresses and subdomains, leveraging Google's dorking capabilities for passive data gathering.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Shodan
Why it's wrong here
Shodan is a search engine for internet-exposed devices, but theHarvester does not query it because Shodan requires an API key and returns IP/service data, not email addresses or domain-related subdomains that theHarvester targets. Moreover, Shodan's data is not indexed for email harvesting; its focus on banners and open ports makes it orthogonal to theHarvester's passive email and subdomain enumeration.
- ✓
Google search
Why this is correct
Google search is a primary source for theHarvester, as it uses search engine queries to passively scrape email addresses and subdomains from indexed pages without interacting directly with target infrastructure. The tool constructs Google dork-like queries (e.g., site:domain.com) and parses results, making it a purely passive OSINT technique for initial reconnaissance.
- ✗
DNS zone transfer
Why it's wrong here
DNS zone transfer is an active reconnaissance technique, because the tester directly queries a DNS server (AXFR request) and, if misconfigured, receives the entire zone file. This is fundamentally different from theHarvester's passive approach, which never sends packets to the target's authoritative servers; it relies on third-party sources like search engines and certificate logs.
- ✗
Social media APIs
Why it's wrong here
theHarvester does not leverage social media APIs because its passive collection model relies on search engine scraping and public certificate transparency logs; querying social APIs would require authentication tokens and violate the tool's lightweight, no-key approach. While social platforms may expose emails in public profiles, theHarvester's architecture predates and does not integrate those endpoints, so attempting to use them would necessitate custom scripting rather than theharvester itself.
Go deeper
Related to this question
Learn chapter
Penetration Testing Tools
Key term
Passive reconnaissance
Passive reconnaissance is the process of gathering information about a target system or network without directly interacting with it, using publicly available sources and stealthy observation.
Key term
theHarvester
theHarvester is an open-source intelligence (OSINT) tool used to gather emails, subdomains, IP addresses, and other public data about a target from search engines and public sources.
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.